INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global data_breach Government CRITICAL 7h Global ransomware Financial Services / Cybersecurity CRITICAL 8h Global vulnerability Information Technology / Cybersecurity CRITICAL 10h Global malware Energy and Utilities CRITICAL 11h Global ransomware Multiple sectors CRITICAL 11h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 13h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 14h Global phishing Multiple sectors HIGH 14h Global insider Cybersecurity Services CRITICAL 14h Global ransomware Multiple sectors (U.S. companies) CRITICAL 15h Global data_breach Government CRITICAL 7h Global ransomware Financial Services / Cybersecurity CRITICAL 8h Global vulnerability Information Technology / Cybersecurity CRITICAL 10h Global malware Energy and Utilities CRITICAL 11h Global ransomware Multiple sectors CRITICAL 11h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 13h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 14h Global phishing Multiple sectors HIGH 14h Global insider Cybersecurity Services CRITICAL 14h Global ransomware Multiple sectors (U.S. companies) CRITICAL 15h Global data_breach Government CRITICAL 7h Global ransomware Financial Services / Cybersecurity CRITICAL 8h Global vulnerability Information Technology / Cybersecurity CRITICAL 10h Global malware Energy and Utilities CRITICAL 11h Global ransomware Multiple sectors CRITICAL 11h Global vulnerability Industrial Control Systems / IoT / Infrastructure CRITICAL 13h Global supply_chain Information Technology and Critical Infrastructure CRITICAL 14h Global phishing Multiple sectors HIGH 14h Global insider Cybersecurity Services CRITICAL 14h Global ransomware Multiple sectors (U.S. companies) CRITICAL 15h

🛡️ CVE Vulnerability Database

CVE vulnerabilities with bilingual AI analysis tailored for Saudi Arabia

CVE ID Title / Description Severity CVSS Status Published
CVE-2026-1482
An out-of-band SQL injection vulnerability (OOB SQLi) has been de…
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluatio…
HIGH
7.5
Jan 27, 2026
CVE-2026-1483
An out-of-band SQL injection vulnerability (OOB SQLi) has been de…
An out-of-band SQL injection vulnerability (OOB SQLi) has been detected in the Performance Evaluatio…
HIGH
7.5
Jan 27, 2026
CVE-2020-36938
WinAVR version 20100110 contains an insecure permissions vulnerab…
WinAVR version 20100110 contains an insecure permissions vulnerability that allows authenticated use…
HIGH
8.8
AI Jan 27, 2026
CVE-2020-36939
Cassandra Web 0.5.0 contains a directory traversal vulnerability …
Cassandra Web 0.5.0 contains a directory traversal vulnerability that allows unauthenticated attacke…
HIGH
7.5
Jan 27, 2026
CVE-2020-36942
Victor CMS 1.0 contains a file upload vulnerability that allows a…
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malici…
HIGH
8.8
AI Jan 27, 2026
CVE-2020-36951
Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vul…
Phpscript-sgh 0.1.0 contains a time-based blind SQL injection vulnerability in the admin interface t…
HIGH
8.2
Jan 27, 2026
CVE-2020-36980
SAntivirus IC 10.0.21.61 contains an unquoted service path vulner…
SAntivirus IC 10.0.21.61 contains an unquoted service path vulnerability in its Windows service conf…
HIGH
7.8
Jan 27, 2026
CVE-2020-36981
Motorola Device Manager 2.4.5 contains an unquoted service path v…
Motorola Device Manager 2.4.5 contains an unquoted service path vulnerability in the PST Service tha…
HIGH
7.8
Jan 27, 2026
CVE-2020-36982
Motorola Device Manager 2.5.4 contains an unquoted service path v…
Motorola Device Manager 2.5.4 contains an unquoted service path vulnerability in the MotoHelperServi…
HIGH
7.8
Jan 27, 2026
CVE-2020-36983
Quick 'n Easy FTP Service 3.2 contains an unquoted service path v…
Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local atta…
HIGH
7.8
Jan 27, 2026
CVE-2021-47902
Testa Online Test Management System 3.4.7 contains a SQL injectio…
Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attacke…
HIGH
8.2
Jan 27, 2026
CVE-2026-21417
Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, c…
Dell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Pass…
HIGH
7.0
Jan 27, 2026
CVE-2026-24345
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1…
Cross-Site Request Forgery in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to bypa…
HIGH
8.8
Jan 27, 2026
CVE-2026-24477
AnythingLLM is an application that turns pieces of content into c…
AnythingLLM is an application that turns pieces of content into context that any LLM can use as refe…
HIGH
7.5
Jan 27, 2026
CVE-2026-24486
Python-Multipart is a streaming multipart parser for Python. Prio…
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Travers…
HIGH
8.6
Jan 27, 2026
CVE-2026-24748
Kargo manages and automates the promotion of software artifacts. …
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.8.7, 1.7.7, and…
HIGH
7.2
Jan 27, 2026
CVE-2026-24882
In GnuPG before 2.5.17, a stack-based buffer overflow exists in t…
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PK…
HIGH
8.4
Jan 27, 2026
CVE-2026-24428
Shenzhen Tenda W30E V2 firmware versions up to and including V16.…
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) contain an authorizat…
HIGH
8.8
Jan 26, 2026
CVE-2026-24430
Shenzhen Tenda W30E V2 firmware versions up to and including V16.…
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive ac…
HIGH
7.5
Jan 26, 2026
CVE-2026-24440
Shenzhen Tenda W30E V2 firmware versions up to and including V16.…
Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) allow account passwor…
HIGH
8.8
Jan 26, 2026
CVE-2025-14459
A flaw was found in KubeVirt Containerized Data Importer (CDI). T…
A flaw was found in KubeVirt Containerized Data Importer (CDI). This vulnerability allows a user to …
HIGH
8.5
Jan 26, 2026
CVE-2025-59473
SQL Injection vulnerability in the Structure for Admin authentica…
SQL Injection vulnerability in the Structure for Admin authenticated user
HIGH
7.2
Jan 26, 2026
CVE-2026-0810
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_s…
A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings c…
HIGH
7.1
Jan 26, 2026
CVE-2026-1428
Single Sign-On Portal System developed by WellChoose has a OS Com…
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allow…
HIGH
8.8
Jan 26, 2026
CVE-2020-36952
IObit Uninstaller 10 Pro contains an unquoted service path vulner…
IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to …
HIGH
7.8
Jan 26, 2026
🤖 AI Analysis Active
AI analysis includes: Arabic description, Saudi impact assessment, remediation steps, compliance mapping (NCA ECC, SAMA CSF, ISO 27001) and MITRE ATT&CK techniques.
💡 Search Tips
CVE-2024-12345 Search by exact ID
apache Search by product name
remote code execution Search by vulnerability type
log4j Search by common name
📡 Data Sources
NVD (NIST) · CIRCL
CISA KEV · ThreatFox
Feodo Tracker · AlienVault OTX
Auto-updated daily via cron
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.